1 /* filter.c - routines for parsing and dealing with filters */
12 static int get_filter_list(Connection *conn, BerElement *ber, Filter **f, char **fstr);
13 static int get_substring_filter(Connection *conn, BerElement *ber, Filter *f, char **fstr);
16 get_filter( Connection *conn, BerElement *ber, Filter **filt, char **fstr )
23 Debug( LDAP_DEBUG_FILTER, "begin get_filter\n", 0, 0, 0 );
26 * A filter looks like this coming in:
28 * and [0] SET OF Filter,
29 * or [1] SET OF Filter,
31 * equalityMatch [3] AttributeValueAssertion,
32 * substrings [4] SubstringFilter,
33 * greaterOrEqual [5] AttributeValueAssertion,
34 * lessOrEqual [6] AttributeValueAssertion,
35 * present [7] AttributeType,,
36 * approxMatch [8] AttributeValueAssertion
37 * extensibleMatch [9] MatchingRuleAssertion
40 * SubstringFilter ::= SEQUENCE {
42 * SEQUENCE OF CHOICE {
43 * initial [0] IA5String,
49 * MatchingRuleAssertion ::= SEQUENCE {
50 * matchingRule [1] MatchingRuleId OPTIONAL,
51 * type [2] AttributeDescription OPTIONAL,
52 * matchValue [3] AssertionValue,
53 * dnAttributes [4] BOOLEAN DEFAULT FALSE
58 f = (Filter *) ch_malloc( sizeof(Filter) );
63 f->f_choice = ber_peek_tag( ber, &len );
65 switch ( f->f_choice ) {
66 case LDAP_FILTER_EQUALITY:
67 Debug( LDAP_DEBUG_FILTER, "EQUALITY\n", 0, 0, 0 );
68 if ( (err = get_ava( ber, &f->f_ava )) == LDAP_SUCCESS ) {
69 *fstr = ch_malloc(4 + strlen( f->f_avtype ) +
71 sprintf( *fstr, "(%s=%s)", f->f_avtype,
72 f->f_avvalue.bv_val );
76 case LDAP_FILTER_SUBSTRINGS:
77 Debug( LDAP_DEBUG_FILTER, "SUBSTRINGS\n", 0, 0, 0 );
78 err = get_substring_filter( conn, ber, f, fstr );
82 Debug( LDAP_DEBUG_FILTER, "GE\n", 0, 0, 0 );
83 if ( (err = get_ava( ber, &f->f_ava )) == LDAP_SUCCESS ) {
84 *fstr = ch_malloc(5 + strlen( f->f_avtype ) +
86 sprintf( *fstr, "(%s>=%s)", f->f_avtype,
87 f->f_avvalue.bv_val );
92 Debug( LDAP_DEBUG_FILTER, "LE\n", 0, 0, 0 );
93 if ( (err = get_ava( ber, &f->f_ava )) == LDAP_SUCCESS ) {
94 *fstr = ch_malloc(5 + strlen( f->f_avtype ) +
96 sprintf( *fstr, "(%s<=%s)", f->f_avtype,
97 f->f_avvalue.bv_val );
101 case LDAP_FILTER_PRESENT:
102 Debug( LDAP_DEBUG_FILTER, "PRESENT\n", 0, 0, 0 );
103 if ( ber_scanf( ber, "a", &f->f_type ) == LBER_ERROR ) {
107 attr_normalize( f->f_type );
108 *fstr = ch_malloc( 5 + strlen( f->f_type ) );
109 sprintf( *fstr, "(%s=*)", f->f_type );
113 case LDAP_FILTER_APPROX:
114 Debug( LDAP_DEBUG_FILTER, "APPROX\n", 0, 0, 0 );
115 if ( (err = get_ava( ber, &f->f_ava )) == LDAP_SUCCESS ) {
116 *fstr = ch_malloc(5 + strlen( f->f_avtype ) +
117 f->f_avvalue.bv_len);
118 sprintf( *fstr, "(%s~=%s)", f->f_avtype,
119 f->f_avvalue.bv_val );
123 case LDAP_FILTER_AND:
124 Debug( LDAP_DEBUG_FILTER, "AND\n", 0, 0, 0 );
125 if ( (err = get_filter_list( conn, ber, &f->f_and, &ftmp ))
127 if (ftmp == NULL) ftmp = ch_strdup("");
128 *fstr = ch_malloc( 4 + strlen( ftmp ) );
129 sprintf( *fstr, "(&%s)", ftmp );
135 Debug( LDAP_DEBUG_FILTER, "OR\n", 0, 0, 0 );
136 if ( (err = get_filter_list( conn, ber, &f->f_or, &ftmp ))
138 if (ftmp == NULL) ftmp = ch_strdup("");
139 *fstr = ch_malloc( 4 + strlen( ftmp ) );
140 sprintf( *fstr, "(|%s)", ftmp );
145 case LDAP_FILTER_NOT:
146 Debug( LDAP_DEBUG_FILTER, "NOT\n", 0, 0, 0 );
147 (void) ber_skip_tag( ber, &len );
148 if ( (err = get_filter( conn, ber, &f->f_not, &ftmp )) == LDAP_SUCCESS ) {
149 if (ftmp == NULL) ftmp = ch_strdup("");
150 *fstr = ch_malloc( 4 + strlen( ftmp ) );
151 sprintf( *fstr, "(!%s)", ftmp );
157 Debug( LDAP_DEBUG_ANY, "decoding filter error\n",
163 Debug( LDAP_DEBUG_ANY, "unknown filter type %lu\n",
165 err = LDAP_PROTOCOL_ERROR;
169 if ( err != LDAP_SUCCESS ) {
171 if ( *fstr != NULL ) {
178 Debug( LDAP_DEBUG_FILTER, "end get_filter %d\n", err, 0, 0 );
183 get_filter_list( Connection *conn, BerElement *ber, Filter **f, char **fstr )
191 Debug( LDAP_DEBUG_FILTER, "begin get_filter_list\n", 0, 0, 0 );
195 for ( tag = ber_first_element( ber, &len, &last ); tag != LBER_DEFAULT;
196 tag = ber_next_element( ber, &len, last ) )
198 if ( (err = get_filter( conn, ber, new, &ftmp )) != LDAP_SUCCESS )
200 if ( *fstr == NULL ) {
203 *fstr = ch_realloc( *fstr, strlen( *fstr ) +
204 strlen( ftmp ) + 1 );
205 strcat( *fstr, ftmp );
208 new = &(*new)->f_next;
212 Debug( LDAP_DEBUG_FILTER, "end get_filter_list\n", 0, 0, 0 );
213 return( LDAP_SUCCESS );
217 get_substring_filter(
230 Debug( LDAP_DEBUG_FILTER, "begin get_substring_filter\n", 0, 0, 0 );
232 if ( ber_scanf( ber, "{a" /*}*/, &f->f_sub_type ) == LBER_ERROR ) {
235 attr_normalize( f->f_sub_type );
236 syntax = attr_syntax( f->f_sub_type );
237 f->f_sub_initial = NULL;
239 f->f_sub_final = NULL;
241 *fstr = ch_malloc( strlen( f->f_sub_type ) + 3 );
242 sprintf( *fstr, "(%s=", f->f_sub_type );
243 for ( tag = ber_first_element( ber, &len, &last ); tag != LBER_DEFAULT;
244 tag = ber_next_element( ber, &len, last ) )
246 rc = ber_scanf( ber, "a", &val );
247 if ( rc == LBER_ERROR ) {
250 if ( val == NULL || *val == '\0' ) {
254 return( LDAP_INVALID_SYNTAX );
256 value_normalize( val, syntax );
259 case LDAP_SUBSTRING_INITIAL:
260 Debug( LDAP_DEBUG_FILTER, " INITIAL\n", 0, 0, 0 );
261 if ( f->f_sub_initial != NULL ) {
262 return( LDAP_PROTOCOL_ERROR );
264 f->f_sub_initial = val;
265 *fstr = ch_realloc( *fstr, strlen( *fstr ) +
267 strcat( *fstr, val );
270 case LDAP_SUBSTRING_ANY:
271 Debug( LDAP_DEBUG_FILTER, " ANY\n", 0, 0, 0 );
272 charray_add( &f->f_sub_any, val );
273 *fstr = ch_realloc( *fstr, strlen( *fstr ) +
275 strcat( *fstr, "*" );
276 strcat( *fstr, val );
279 case LDAP_SUBSTRING_FINAL:
280 Debug( LDAP_DEBUG_FILTER, " FINAL\n", 0, 0, 0 );
281 if ( f->f_sub_final != NULL ) {
282 return( LDAP_PROTOCOL_ERROR );
284 f->f_sub_final = val;
285 *fstr = ch_realloc( *fstr, strlen( *fstr ) +
287 strcat( *fstr, "*" );
288 strcat( *fstr, val );
292 Debug( LDAP_DEBUG_FILTER, " unknown type\n", tag, 0,
294 return( LDAP_PROTOCOL_ERROR );
297 *fstr = ch_realloc( *fstr, strlen( *fstr ) + 3 );
298 if ( f->f_sub_final == NULL ) {
299 strcat( *fstr, "*" );
301 strcat( *fstr, ")" );
303 Debug( LDAP_DEBUG_FILTER, "end get_substring_filter\n", 0, 0, 0 );
304 return( LDAP_SUCCESS );
308 filter_free( Filter *f )
316 switch ( f->f_choice ) {
317 case LDAP_FILTER_EQUALITY:
320 case LDAP_FILTER_APPROX:
321 ava_free( &f->f_ava, 0 );
324 case LDAP_FILTER_SUBSTRINGS:
325 if ( f->f_sub_type != NULL ) {
326 free( f->f_sub_type );
328 if ( f->f_sub_initial != NULL ) {
329 free( f->f_sub_initial );
331 charray_free( f->f_sub_any );
332 if ( f->f_sub_final != NULL ) {
333 free( f->f_sub_final );
337 case LDAP_FILTER_PRESENT:
338 if ( f->f_type != NULL ) {
343 case LDAP_FILTER_AND:
345 case LDAP_FILTER_NOT:
346 for ( p = f->f_list; p != NULL; p = next ) {
353 Debug( LDAP_DEBUG_ANY, "unknown filter type %lu\n",
363 filter_print( Filter *f )
369 fprintf( stderr, "NULL" );
372 switch ( f->f_choice ) {
373 case LDAP_FILTER_EQUALITY:
374 fprintf( stderr, "(%s=%s)", f->f_ava.ava_type,
375 f->f_ava.ava_value.bv_val );
379 fprintf( stderr, "(%s>=%s)", f->f_ava.ava_type,
380 f->f_ava.ava_value.bv_val );
384 fprintf( stderr, "(%s<=%s)", f->f_ava.ava_type,
385 f->f_ava.ava_value.bv_val );
388 case LDAP_FILTER_APPROX:
389 fprintf( stderr, "(%s~=%s)", f->f_ava.ava_type,
390 f->f_ava.ava_value.bv_val );
393 case LDAP_FILTER_SUBSTRINGS:
394 fprintf( stderr, "(%s=", f->f_sub_type );
395 if ( f->f_sub_initial != NULL ) {
396 fprintf( stderr, "%s", f->f_sub_initial );
398 if ( f->f_sub_any != NULL ) {
399 for ( i = 0; f->f_sub_any[i] != NULL; i++ ) {
400 fprintf( stderr, "*%s", f->f_sub_any[i] );
403 charray_free( f->f_sub_any );
404 if ( f->f_sub_final != NULL ) {
405 fprintf( stderr, "*%s", f->f_sub_final );
409 case LDAP_FILTER_PRESENT:
410 fprintf( stderr, "%s=*", f->f_type );
413 case LDAP_FILTER_AND:
415 case LDAP_FILTER_NOT:
416 fprintf( stderr, "(%c", f->f_choice == LDAP_FILTER_AND ? '&' :
417 f->f_choice == LDAP_FILTER_OR ? '|' : '!' );
418 for ( p = f->f_list; p != NULL; p = p->f_next ) {
421 fprintf( stderr, ")" );
425 fprintf( stderr, "unknown type %lu", f->f_choice );
430 #endif /* ldap_debug */